medium · CVSS v3 4.3 · CVSS v4 5.3 · EPSS 0.00271
CVE-2026-96764
kvcache-ai mooncake up to 0.3.12/0.3.14-rc1 contains a resource allocation flaw in MasterService::GetReplicaListByRegex. Remote attackers ca
Overview
kvcache-ai mooncake up to 0.3.12/0.3.14-rc1 contains a resource allocation flaw in MasterService::GetReplicaListByRegex. Remote attackers can trigger excessive memory usage, potentially leading to denial of service. The vulnerability is publicly known and unpatched.
Description
A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1. Impacted is the function MasterService::GetReplicaListByRegex of the component Regular Expression Handler. Executing a manipulation can lead to allocation of resources. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Impact
The flaw allows attackers to cause uncontrolled resource consumption, compromising availability. Defenders must monitor memory usage and service responsiveness. The vulnerability does not directly expose data or confidentiality. It primarily threatens the integrity of service uptime.
Remediation
Apply the vendor's patch when released. In the meantime, restrict network access to the MasterService endpoint, limit regex complexity, and enforce rate limiting or resource quotas on the service.
Risk context
Medium severity (CVSS 4.3/5.3) and low EPSS (0.00271) indicate a moderate risk but still actionable. Defenders should prioritize monitoring and apply mitigations promptly.
Affected products
- kvcache-ai mooncake
Scores
- Severity
- medium
- CVSS v2
- 4
- CVSS v3
- 4.3
- CVSS v4
- 5.3
- EPSS
- 0.00271